Courseiva
hardMultiple Choice

PT0-002 Practice Question: A tester is analyzing a piece of malware and…

A tester is analyzing a piece of malware and needs to identify the original entry point after unpacking. Which technique is most appropriate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Original Entry Point (OEP) finding

Finding the Original Entry Point (OEP) is a standard step after unpacking to resume analysis. Option B is wrong because hash analysis identifies known malware. Option C is wrong because import hash matching identifies library versions. Option D is wrong because code signing verification checks authenticity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Original Entry Point (OEP) finding

    Why this is correct

    Finding the Original Entry Point (OEP) is essential when analyzing packed or encrypted malware. The packer begins execution in an unpacking stub that decompresses the payload in memory and then jumps to the OEP, where the true program logic starts. Locating the OEP enables an analyst to dump the unpacked process and statically analyze the deobfuscated code, using breakpoints on common OEP heuristics or tools like Scylla and OllyDump.

  • ✗

    Hash analysis

    Why it's wrong here

    Hash analysis computes a cryptographic fingerprint such as MD5, SHA-1, or SHA-256 for the entire malware file. This unique digest is used to query threat-intelligence platforms and verify whether a sample has been seen before, but it does not provide any structural or runtime information. Consequently, hashing cannot indicate where the unpacker ends or where the original code begins, making it irrelevant for OEP discovery.

  • ✗

    Import hash matching

    Why it's wrong here

    Import hash matching (impHash) applies a fuzzy hashing algorithm to the import table, generating a signature that clusters malware samples with similar API call sequences. Although impHash helps identify related families and potential evasions, it functions at the metadata level and does not inspect executable code or control flow. Thus it cannot locate the transition point from an unpacking stub to the original program's entry point.

  • ✗

    Code signing verification

    Why it's wrong here

    Code signing verification checks the authenticity and integrity of a binary by validating its Authenticode or similar digital signature against a trusted certificate store. This process confirms who signed the file and that it hasn't been tampered with, but it reveals nothing about the internal layout or execution flow. A packed executable may retain a valid signature, so signature verification cannot be used to find the OEP in an already-unpacked or malicious sample.

About these practice questions

One of 777 original PT0-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PT0-003 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PT0-003 exam.